For your web inspector console: $("body").html($("body").html().replace(/Clyde Frog/g, "the NSA")) Update: more proper $("body").html($("body").html().replace(/Clyde[\s\r\n]Frog/g, "the NSA").replace(/\. t/g, ". T"))
That's not perfectly accurate; the reason I think an abstract name is helpful is that GCHQ is just as bad, if not worse: it's handy to have a name that captures all of them.
Is Extended Random a Malicious NSA Plot?
41–50 of 56 posts
Re: Is Extended Random a Malicious NSA Plot?
#42Just out of curiosity, are those jabber chat rooms public? tptacek mentions some jabber logs of the TLS working group.
Re: Is Extended Random a Malicious NSA Plot?
#43https://bugzilla.mozilla.org/show_bug.cgi?id=1001989 Bug 1001989 - NSA partisan coder Steps to reproduce: I found a big bug in Mozilla. Would you please remove Eric Rescorla and other NSA-partisans from your software? Actual results: NSA partisans were introducing bugs and vulnerabilites into Mozilla. Sourcecode is not published. Expected results: Remove NSA partisans from Mozilla., publish the sourcecode.
Re: Is Extended Random a Malicious NSA Plot?
#44Earlier quoted context omitted.
> symmetric is sufficient for nation-state security Is that a verifiable assertion? Would love to read more about it.
Governments can afford to employ people to transport N^2 keying material. Additionally, they have predefined communications patterns. Even if part of the government moves to asymmetric algorithms for key distribution (only possible after the discovery of Diffie-Hellman), the top secret portions can continue using couriers to avoid relying on an additional algorithm. Combined with its standard use for bulk ciphering,…
A lot of interesting information about the history I learned from Steven Levy's crypto: http://www.amazon.com/Crypto-Rebels-Government-Privacy-Digit...
Re: Is Extended Random a Malicious NSA Plot?
#45I hate to ask a dumb question, but the article discusses the actions of Clyde Frog a lot. Is Clyde Frog a person, a company, a government project, or what? A web search found a TV show and a stuffed animal, so I'm honestly puzzled. Edit: thanks cmg. I was reading the article on my phone and the side notes were off screen so I totally missed the explanation.
Re: Is Extended Random a Malicious NSA Plot?
#46Earlier quoted context omitted.
Governments can afford to employ people to transport N^2 keying material. Additionally, they have predefined communications patterns. Even if part of the government moves to asymmetric algorithms for key distribution (only possible after the discovery of Diffie-Hellman), the top secret portions can continue using couriers to avoid relying on an additional algorithm. Combined with its standard use for bulk ciphering,…
Public Key crypto was discovered by GCHQ (and then given to the NSA) several years before it was publicly discovered by Diffie-Hellman and RSA. I think this was to avoid having to have the symmetric keys under armed guard. The public discovery is also what kicked off the 'crypto wars'. I'd be surprised if modern nation state intelligence communities found symmetric encryption sufficient. A lot of interesting informat…
Spooks would of course welcome any discovery, and asymmetric crypto does solve problems for them (getting government crypto distributed as wide as possible). I am saying purely symmetric is "sufficient" for their core functionality - the communications that really need to be secret. Coupled with the head start before asymmetric was even discovered, that is where their focus is going to be.
Put another way: if you were in charge of securing communications and had to prioritize resources, would you rather research a trustworthy asymmetric algorithm or a trusty symmetric algorithm? Likewise if you wanted to snoop on others' communications, would you prioritize breaking symmetric or asymmetric techniques?
Re: Is Extended Random a Malicious NSA Plot?
#47Re: Is Extended Random a Malicious NSA Plot?
#48https://bugzilla.mozilla.org/show_bug.cgi?id=1001989 Bug 1001989 - NSA partisan coder Steps to reproduce: I found a big bug in Mozilla. Would you please remove Eric Rescorla and other NSA-partisans from your software? Actual results: NSA partisans were introducing bugs and vulnerabilites into Mozilla. Sourcecode is not published. Expected results: Remove NSA partisans from Mozilla., publish the sourcecode.
Mozilla was much kinder to you in their response than you deserve: https://bugzilla.mozilla.org/show_bug.cgi?id=1001989
Re: Is Extended Random a Malicious NSA Plot?
#49https://bugzilla.mozilla.org/show_bug.cgi?id=1001989 Bug 1001989 - NSA partisan coder Steps to reproduce: I found a big bug in Mozilla. Would you please remove Eric Rescorla and other NSA-partisans from your software? Actual results: NSA partisans were introducing bugs and vulnerabilites into Mozilla. Sourcecode is not published. Expected results: Remove NSA partisans from Mozilla., publish the sourcecode.
Mozilla was much kinder to you in their response than you deserve: https://bugzilla.mozilla.org/show_bug.cgi?id=1001989
Reported: 2014-04-27 03:09 PDT by Zakharias
https://bugzilla.mozilla.org/show_bug.cgi?id=993224
Reported: 2014-04-07 19:02 PDT by Katrien
So why do you believe that Mozilla shouldn't remove NSA stooges and partisans from their software and audit their contributions? Doesn't that fall under their mission to "protect Firefox from the NSA"?
Mozilla calls on users to protect Firefox from the NSA: http://www.wired.co.uk/news/archive/2014-01/15/mozilla
Brendan Eich's Blog: Trust but Verify: https://brendaneich.com/2014/01/trust-but-verify/
Call to Action
To ensure that no one can inject undetected surveillance code into Firefox, security researchers and organizations should:
regularly audit Mozilla source and verified builds by all effective means;
establish automated systems to verify official Mozilla builds from source; and
raise an alert if the verified bits differ from official bits.
[...] Through international collaboration of independent entities we can give users the confidence that Firefox cannot be subverted without the world noticing, and offer a browser that verifiably meets users’ privacy expectations.
Re: Is Extended Random a Malicious NSA Plot?
#50Earlier quoted context omitted.
Mozilla was much kinder to you in their response than you deserve: https://bugzilla.mozilla.org/show_bug.cgi?id=1001989
Good for you, that's the exact same link I posted, and if you'll read the whole bug report like I did, you'll see that I'm not the one who reported it, nor the one who reported the duplicate. Reported: 2014-04-27 03:09 PDT by Zakharias https://bugzilla.mozilla.org/show_bug.cgi?id=993224 Reported: 2014-04-07 19:02 PDT by Katrien So why do you believe that Mozilla shouldn't remove NSA stooges and partisans from their s…